Some Ubuntu security patches are now behind 'Ubuntu Pro', a paid product
cloudisland.nz
cloudisland.nz
They can only make these patches because large enterprises wanted them and were willing to pay for them, and they have found a nice way to make the patches available free to you and me. If they made them free for large enterprises too, that funding would go away and we would all lose them.
Also, the extra security work on universe means there are more people who can handle the main repo even better. So even non-Pro users have benefitted.
Free riding isn't always available. Have you helped the community in any way?
The Canonical security team and wider Ubuntu contributors will still make best efforts to update universe. Neither the team nor I are interested in degrading a prior experience for our free users. We know what the criteria were for those best-effort universe updates, and they remain unchanged.
What's changed is that there is now a much larger team that will systematically fix every high and critical vulnerability in universe, with an SLA. That's a huge improvement, it's great for enterprise users, it enables people to use Ubuntu in regulated and mission-critical environments. It also makes me very happy that we give it free for personal use on 5 machines.
Over the years, companies have started asking us to do more for them in universe, and now that body of work is available to all customers. We are making it freely available to you and others under a personal subscription. I think that's rather elegant, I hope more and more companies see Ubuntu Pro as a very cost-effective way to get full compliance for their estates, and I hope we can keep growing the set of things we make available for free as a result.
If you look at the range of packages covered, and the numbers of issues addressed, it's way, way more than any other enterprise Linux offering. If it were possible to provide enterprises with this level of security update coverage for free, then I'm sure someone would have figured out how to do that. I couldn't figure out how to fund full security coverage of universe without having customers for that work. In the end, I think the Ubuntu Pro free personal subscription is a very nice way to balance what are ultimately conflicting desires between people who quite understandably want more and more for free, and people who are able to buy the work that they need.
Ubuntu Pro promises 10 years of security updates to some of the packages in the universe repo.
In Redhat speak, this is like RH supporting some EPEL packages if you have a subscription.
To the best of my knowledge, RH won't touch EPEL with a 10 foot pole.
Which is worse: putting asbestos in everything because you don't know it's harmful yet, or once everyone learns that it is harmful, having a cheap product line that you put asbestos in and an expensive product line that you don't?
We've all decided to build with sustainable local materials, which anybody can dig up without harming the environment. That's wonderful! Unfortunately, the materials sometimes turn out to have asbestos in them.
Canonical and a large number of friends enjoy digging, and they make those local materials available for free, no digging required, as Ubuntu. So Ubuntu happens to be a free source of pre-dug materials which is popular for lots of reasons.
People with big buildings who like using Ubuntu need the asbestos removed if its found, and Canonical has started to do that for them commercially. Canonical have also said they are happy to remove the asbestos for free for small buildings, as long as the big-building people keep funding them to do it. The more big building people choose Canonical to sort out this issue, the better it will be for everyone using Ubuntu, even if they don't do any digging themselves.
Seems like a great deal for people with smaller buildings, as long as people with big buildings also think it's a good deal. Since I happy to like helping people with smaller buildings, I think this is all pretty square.
Now I'm REALLY glad I switched my entire infrastructure over to Debian last year.
Snap drives users away. Here are some recent relevant HN threads:
Ubuntu Snap update spoiled my World Cup Final - https://news.ycombinator.com/item?id=34041272
Ubuntu: “How are we improving Firefox snap performance?” - https://news.ycombinator.com/item?id=32702062
Ask HN: Is it safe to remove snap from Ubuntu 22.04 LTS completely? - https://news.ycombinator.com/item?id=31198675
Firefox now only available via snap on Ubuntu - https://news.ycombinator.com/item?id=30776698
Ubuntu to Make Firefox Snap Default in 21.10 - https://news.ycombinator.com/item?id=28564600
Ubuntu 20.04 LTS’ snap obsession has snapped me off of it - https://news.ycombinator.com/item?id=24383276
Once my current 20.04 snowflakes fall out of security patch support and need a major OS upgrade, I won't be using Ubuntu at all ever again. There's no advantage over Debian, quite the contrary. Sadly, now Ubuntu is the disadvantage OS.
snap is installed on ubuntu server too, and if some junior engineer comes in, how are they supposed to know not to use it?
How are they supposed to know that after googling some variation on "install docker ubuntu" and getting "snap install docker" (https://snapcraft.io/docker), they should ignore those very official looking instructions which will give them a broken and buggy docker installation?
Perhaps the problem's theoretical, but canonical certainly encourages using snaps on servers, such as in the microk8s docs (https://microk8s.io/docs/getting-started), and I expect if canonical keeps pushing it, it'll become more and more of a server problem in reality too.
ZFS support: https://www.omgubuntu.co.uk/2023/01/ubuntu-zfs-support-statu...
It's hard to put ones finger on a particular thing, but I've felt for some time now that Ubuntu is becoming increasingly user-hostile in the pursuit of money.
It was a similar kind of user-hostility that drove me away from Red Hat (when they started locking user-supplied support forums behind subscriptions).
Nowadays Debian isn't lagging behind anymore, thankfully.
Ubuntu used to fit between Testing and Sid.
I only have Ubuntu server on my NAS. Everything else is Debian.
Considering switching the NAS to FreeBSD
Specifically about Debian. I find more than 1 year old versions pretty outdated. I couldn't try Go generics because the version was too old... that pissed me off.
The learning curve for something like podman really isn't that steep, and a relatively small investment in learning that has paid many dividends for me through the last few years.
Debian is fine, but RHEL-derivates are most reliable because they run at scale and have the most stable kernel going.
CentOS (5 year lifecycle) is patched more often than Alma and Rocky (10 year lifecycle), so there's no "perfect" alternative free to RHEL. Large enterprises should be purchasing RHEL because most multibillion dollar companies run Cent or one copy of RHEL.
Also, I wouldn't use RPMs because they muddy the boundaries between OS and app: nix, microdnf, or habitat where all of "your" stuff is isolated and vendored separately. At the boundaries, it's important to sanitize environment variables, PATH, and shebangs that could cause bleed through. When in doubt, create a minimal chroot environment (even within containerization, and use SELinux) because apps shouldn't be able to run wild over a system.
Then s6 or a daemon tools-derivative non-init process supervisor that doesn't replace init is also important since Systemd is unreliable for real apps.
That makes it sound as if Canonical has taken some kind of responsibility for making these packages secure at a cost for more than five devices.
FOSS users: "I'm gonna take it for granted and if someone ever wants to charge me money for anything open source I'm gonna be very angry".
https://discourse.ubuntu.com/t/why-is-extended-security-main...
``` Canonical has never provided security updates for universe packages until this week, so nothing has changed for you if you decide to simply ignore the message ```
Is that true, though? Until now, wasn't it just that they weren't guaranteed? Didn't Canonical make security patches available in universe on a "best-effort" basis, or at least say they did?
My reasoning was that if we were running a supported version of $oss_project then we'd get security updated naturally.
Package maintenance is time consuming and difficult. It requires a lot of volunteer work. Individual maintainers are overworked and unpaid. Packaging software often requires managing complex dependencies, writing documentation, developing packaging toolchains, and patching software.
Furthermore, stable release of a particular software version is even more of a challenge for package maintainers. Often upstream FOSS maintains only patch HEAD and release a new version. The responsibility of backporting changes to previous versions is left to package maintainers. To provide secure versions of old software, you're asking maintainers to have intimate familiarity with the OSS code bases and follow the dev process etc.
If I had community supported software exposed to the internet, I would be very concerned with the current state of things. I would want to ensure that individuals are invested with maintaining this software in a full-time capacity. It is important that "main" receives free Updates. Ubuntu Pro seems like it enhances the OSS ecosystem. As an personal user, you can get a free subscription courtesy of Canonical.
It is important to remember that as the end user, you are choosing to enable the community repo. Without Canonical, you wouldn't even know this version of the software is vulnerable.
* Individual users can use it for free on up to 5 machines.
if they're distributing under gpl, that means they 1) have to make the source available, 2) the user maintains the ability to redistribute.
So provided that the user makes their own apt repo, they should be able to distribute it to as many machines as they see fit. That's essentially how centos operated. I'm sure there's some exceptions, around assets that ubuntu may own or any trademarks. But I shouldn't be learning this from an HN link to a twitter post of a screenshot that references ubuntu.com/pro. So I have the sense they haven't done much if any advertising for it? Maybe I've just been oblivious?
It is somewhat concerning that they're kinda holding security packages hostage...but I don't think it's unreasonable for ubuntu to want corporations to chip in. Gotta keep the operation running somehow, and bills don't just pay themselves. I don't know what else they can offer to make anyone actually shell out some cash.
In practice, I think they probably will be able to, since grsecurity can for their patches (at least they've been able to so far) even though the Linux kernel is GPL. I agree that they shouldn't be able to.
[0]: https://github.com/endoflife-date/endoflife.date/pull/2424
[1]: https://deploy-preview-2424--endoflife-date.netlify.app/ubun...
Is this an EOL ubuntu release? In which case this is expected (arguable whether it's good practise or not).
If not, y'know, bugs are also a thing that happens.
Let's see how it plays out.
No, it's happening in 22.04 to me.
> If not, y'know, bugs are also a thing that happens.
I don't think it's a bug, because what's actually happening matches what Canonical's website says is happening.
This is the webpage I'm looking at: https://ubuntu.com/security/esm
In the "Security Patching" comparison between Ubuntu LTS and Ubuntu Pro for the 23,000 Ubuntu Universe packages, they say "Best effort" for Ubuntu LTS v/s "10 years for Ubuntu Pro". This would lead a reasonable person to think "Okay, maybe it's 2-3 years at least for LTS?"
But in the graphic below for Universe, there is no orange section (unlike the 5 year line for Ubuntu Main). Which I think that Ubuntu LTS will now never guarantee any security patches for Universe, even if the distro came out yesterday.
Am I reading this wrong? I hope I am, but it seems to match people's experience.
Canonical are letting home users, community, power users and small businesses benefit free of charge from the extra security work that much larger enterprise customers had asked for, and funded. If Canonical made it free for the large enterprises, they would stop funding it and we would all lose the best and broadest security coverage in the market. Also, the Canonical security team has grown a lot to do this work, so the security coverage of Ubuntu ‘main’ which has always been there is now even better.
So this is pure win for you, me, and everybody else on Ubuntu too.
If you don’t change anything, you get more free security fixes in Ubuntu than any other Linux you could pay for, for 5 years, and that keeps improving as more big companies use Ubuntu Pro. With a free subscription you get personal / small biz coverage that’s miles better than any other enterprise offering. And if you are a large business, Ubuntu Pro is an incredibly cost-effective way to get full coverage and things like FIPS and FedRAMP coverage while letting your developers use any of the tens of thousands of Ubuntu packages. It’s 3-4% of the cost of the cloud VM, a total no-brainier for any CISO.
There is a reason the fast-moving companies are building new stuff on Ubuntu.